PT-2026-61006 · Xrdp+1 · Xrdp+1

CVE-2026-44178

·

Published

2026-07-08

·

Updated

2026-08-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6.1
Description A heap-based buffer overflow exists in the virtual channel forwarding mechanism. The process uses a fixed-size buffer without adequate bounds checking when forwarding data from a remote client to the internal channel server. An authenticated remote attacker can send a specially crafted virtual channel message that exceeds the buffer capacity, causing heap memory corruption. This can lead to a denial of service or arbitrary code execution with the privileges of the xrdp process.
Recommendations Update to version 0.10.6.1.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44178
GHSA-HH7R-2RMQ-Q4G4
OPENSUSE-SU-2026:11543-1

Affected Products

Red Os
Xrdp